I didn't know where to post this, so I put it here.
Over the last couple months I've seen entries like this in my log files (I obfuscated my domain name *****):
There are a few for each of my domains and the client was refused access with a 401 error in each case, but I'm concerned about the persistance of the attempts. They are all from the same IP address: 168.75.177.2
Arin shows the following for that address:
Has anybody else seen log entries like this?
riley
Over the last couple months I've seen entries like this in my log files (I obfuscated my domain name *****):
Code:
date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) cs(Cookie) cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes cs-bytes time-taken
2004-04-24 18:18:10 66.36.229.77 GET / - 80 guest 168.75.177.2 Mozilla/4.0+(compatible;+MSIE+5.01;+Windows+NT+5.0) - - [url]www.***********.com[/url] 401 1 1326 1812 237 109
Arin shows the following for that address:
Code:
OrgName: ClearBlue Technologies
OrgID: CLEAR-1
Address: 125 Elwood Davis Road
City: Syracuse
StateProv: NY
PostalCode: 13219
Country: US
NetRange: 168.75.0.0 - 168.75.255.255
CIDR: 168.75.0.0/16
NetName: NAVI-A84B0000-16-0
NetHandle: NET-168-75-0-0-1
Parent: NET-168-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.APPLIEDTHEORY.COM
NameServer: NS2.APPLIEDTHEORY.COM
NameServer: NS3.APPLIEDTHEORY.COM
Comment:
RegDate:
Updated: 2004-02-26
Has anybody else seen log entries like this?
riley